<?xml version="1.0" encoding="UTF-8"?><rdf:RDF xmlns="http://purl.org/rss/1.0/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel rdf:about="http://dl.gi.de/handle/20.500.12116/36436">
<title>P312 - Open Identity Summit 2021</title>
<link>http://dl.gi.de/handle/20.500.12116/36436</link>
<description/>
<items>
<rdf:Seq>
<rdf:li rdf:resource="http://dl.gi.de/handle/20.500.12116/36502"/>
<rdf:li rdf:resource="http://dl.gi.de/handle/20.500.12116/36504"/>
<rdf:li rdf:resource="http://dl.gi.de/handle/20.500.12116/36499"/>
<rdf:li rdf:resource="http://dl.gi.de/handle/20.500.12116/36500"/>
</rdf:Seq>
</items>
<dc:date>2026-07-21T13:32:09Z</dc:date>
</channel>
<item rdf:about="http://dl.gi.de/handle/20.500.12116/36502">
<title>Evaluation of Account Recovery Strategies with FIDO2-based Passwordless Authentication</title>
<link>http://dl.gi.de/handle/20.500.12116/36502</link>
<description>Evaluation of Account Recovery Strategies with FIDO2-based Passwordless Authentication
Kunke, Johannes; Wiefling, Stephan; Ullmann, Markus; Lo Iacono, Luigi
Roßnagel, Heiko; Schunck, Christian H.; Mödersheim, Sebastian
Threats to passwords are still very relevant due to attacks like phishing or credential stuffing. One way to solve this problem is to remove passwords completely. User studies on passwordless FIDO2 authentication using security tokens demonstrated the potential to replace passwords. However, widespread acceptance of FIDO2 depends, among other things, on how user accounts can be recovered when the security token becomes permanently unavailable. For this reason, we provide a heuristic evaluation of 12 account recovery mechanisms regarding their properties for FIDO2 passwordless authentication. Our results show that the currently used methods have many drawbacks. Some even rely on passwords, taking passwordless authentication ad absurdum. Still, our evaluation identifies promising account recovery solutions and provides recommendations for further studies.
</description>
<dc:date>2021-01-01T00:00:00Z</dc:date>
</item>
<item rdf:about="http://dl.gi.de/handle/20.500.12116/36504">
<title>How Quantum Computers threat security of PKIs and thus eIDs</title>
<link>http://dl.gi.de/handle/20.500.12116/36504</link>
<description>How Quantum Computers threat security of PKIs and thus eIDs
Vogt, Sebastian; Funke, Holger
Roßnagel, Heiko; Schunck, Christian H.; Mödersheim, Sebastian
Quantum computers threaten the security of asymmetric cryptography and thus the heart of a PKI - used for example to protect electronic data in passports. On the one hand, there are already promising candidates for post-quantum secure algorithms, but these also have disadvantages (stateful and / or with significantly larger public keys or signatures). On the other hand, there are some application areas for which a PKI should use post-quantum secure procedures as soon as possible. What is the situation regarding PQC in the market for secure, electronic identification (e.g. electronic travel documents)? What needs to be done to prepare electronic travel documents for a post-quantum world?
</description>
<dc:date>2021-01-01T00:00:00Z</dc:date>
</item>
<item rdf:about="http://dl.gi.de/handle/20.500.12116/36499">
<title>Open Identity Summit 2021 - Complete Volume</title>
<link>http://dl.gi.de/handle/20.500.12116/36499</link>
<description>Open Identity Summit 2021 - Complete Volume
Roßnagel, Heiko; Schunck, Christian H.; Mödersheim, Sebastian
</description>
<dc:date>2021-01-01T00:00:00Z</dc:date>
</item>
<item rdf:about="http://dl.gi.de/handle/20.500.12116/36500">
<title>Towards the COSCA framework for “COnseptualing Secure CArs”.</title>
<link>http://dl.gi.de/handle/20.500.12116/36500</link>
<description>Towards the COSCA framework for “COnseptualing Secure CArs”.
Bella, Giampaolo; Biondi, Pietro; Costantino, Gianpiero; Matteucci, Ilaria; Marchetti, Mirco
Roßnagel, Heiko; Schunck, Christian H.; Mödersheim, Sebastian
Cyber risks associated with modern cars are often referred to safety. However, modern cars expose a variety of digital services and process a variety of personal data, at least of the driver’s. This paper unfolds the argument that car (cyber-)security and drivers’ privacy are worthy of additional consideration, and does so by advancing “COSCA”, a framework for “COnceptualising Secure CArs” as interconnected nodes of the Next Generation Internet. COSCA adopts an innovative socio-technical approach. It crowdsources drivers’ perceptions on core privacy topics and it classifies the data collected by cars and processed by manufacturers pursuant the General Data Protection Regulation. These steps inform a risk assessment which highlights the more relevant mitigation strategies and cyber security technologies. Finally, COSCA aims at designing novel interfaces to enable drivers to exercise their rights about personal data collection and processing.
</description>
<dc:date>2021-01-01T00:00:00Z</dc:date>
</item>
</rdf:RDF>
